Feed/CVE-2026-48282
CVE-2026-48282CRITICALCVSS 10.0CISA KEV: Actively Exploited

CVE-2026-48282

Published Jun 30, 2026·Updated Aug 24, 2026

NVD Description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Public Exploits & PoCs1 found

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free